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PM Activation & Setup 


To use the Qualys Patch Management (PM) application, the following configuration 
steps are required: 


1. Install Qualys Cloud Agent (CA) on a target host. 
Assign target agent host to CA Configuration Profile that has PM enabled. 


Activate Patch Management (PM) module for target agent host. 
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4. Assign PM license to host 

5. Assign target agent host to PM Assessment Profile (optional) 
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Configure a patch deployment job 


Navigate to the following URL to view the “PM Activation & Setup” tutorial: 


PLAY d Lab 1- https://ior.ad/7PBL 


Configuration Profile 


Cloud Agent 


Patchable hosts must belong to a Cloud Agent Configuration Profile with the “Patch 
Management” module enabled. 


Configuration Profile Creation Tum help tips: On | Off 4 


You're in the Cloud 


SENA Patch Management 
Agent application Step 11 of 11 Enable PM on the 


configuration profile 


General Info w^ Enable PM module for this profile (ДИ) 


Blackout Windows Configuration 


These settings define operational setting for the agent 
Performance 


Cache size 2048 MB (512 - 10240) 
Assign Hosts O Unlimited 


Agent Scan Merge 
Set the Cache size to 


VM Scan Interval store downloaded patches 


PC Scan Interval 


SCA Scan Interval 


FIM 


Ensure the "Enable PM module for this profile" switch is in the "ON" position. 


Cache size - The PM agent will download patches for installation to the host cache. 
Patches are downloaded directly from vendor sites or optionally from Qualys Gateway 
Server (QGS). The cache size configured must be large enough to accommodate all 
patches. Cache size can range from 512 MB - 10 GB, or select the "Unlimited" option to 
prevent patch downloads from exceeding available cache space. 


A 2 GB minimum cache size is recommended for downloading Windows Updates. 


Activate PM Module 


Within the "Cloud Agent" application, the PM module must be activated for "patchable" 
assets. 


Cloud Agent м 


E Helps. ^ ShyamRaj-CORP-Demo w | Logout 
Dashboard Agent Manageme 


You're in the Cloud 


ида ара, АА Agent application 


Agents on Profiles 


Saved Searches + 


м Адепіѕ 
Search... 


е Search 224 


Agent Host os 


Version Last Activity ~ Last Checked In Configuration Agent Modules Tags 
М ЅНАВЕРОІМТ201@ E Microsoft Win... 4.3.1.107 ‘Scan Complete an hour ago *BU-NET-RDLABs-US-.... юш 0s: win бег. 
4 1 ho 
View Asset Details PC Sp [ умов - webs... 
Add Tags Use this option to activate All Assets 
А: Config Profil 
е PM on the host Cloud Agent 
Activate Agent 
Deactivate Agent 


34 more tags 
Uninstall Agent 


oO COMEX2019 Abala ior FIM of GOR o PM С XOR Scan Complete an hour ago *BU-NET-RDLABs-IND... ШЕВ €D EE RDP Assets 
10.11.71.31, fe80:¢ an hour ago ES ES t 
° ta Deactivate Agent for FIM or EDR or PM or XDR | VM Scan: an hour ago RDP 
г Lau ] 
PC Scan: 3 hours ago 


[ умов - serveros 


Use an agent host's “Quick Actions” menu to select the “Activate for PM” option. 
Alternatively, use the Cloud Agent API to activate agents in bulk. 


Assessment Profile 


Patch Management 

Deploy patches to your systems 
Within the “Patch Management” application, an Assessment Profile allows you to 
specify the frequency in which hosts are scanned for missing and installed patches. 
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Patch Management DASHBOARD PATCHES ASSETS 


JOBS CONFIGURATION 


De 
е 
K 


Configuration Profiles ШҮР 


1-30f 3 
System Profile System Every 4 hours 
Default Assessment Profile Jul 23, 2020 
Disabled Assessment Profile trann3zh44 Every 48 hours | Weekly 
Aug 13, 2020 
PM Lab Assessment Profile trann3zh44 Every 24 hours І PM Lab 
PM Lab: Activation & Setup Aug 13, 2020 


By default, any host not assigned to a specific profile will be assigned to the System 
Profile. 


PM Deployment Job 


While a patch assessment profile provides a list of “installed” and “missing” patches, 
“Deployment Jobs” perform the task of installing patches on the hosts. 


Navigate to the following URL to view the “PM Deployment Job” tutorial: 


Lab 2 - https://ior.ad/7PBM 


Before creating any job, you’ll need to add “patchable” agent hosts to the “Licenses” tab 
(within the CONFIGURATION section of the Patch Management application). 


Patch Management DASHBOARD PATCHES ASSETS JOBS CONFIGURATION 


Configuration ДОД Licenses 
License Consumption 


Patch Management Total Consumption 


Type: TRIAL El 
Expiring in: 24 days on 12 Sep, 2020 18:59 PM Status: Active 


100% 


License Details 


Licenses Purchased Licenses Used 
10 2 


Select assets for patch management 


Select asset tags to include or exclude for patch management. Total Consumption counter shows the number of licenses used 
based on the number of matching assets contained in the included asset tags. 


Include Assets Tags Select Tags 
| PMLab x 


Add Exclusion Asset Tags 


Use Asset Tags to include hosts for license consumption. The “Total Consumption” 
indicator is updated with the number of agent hosts included in the selected tags. 


Create Deployment Job 


You can create a “Deployment Job” for agent hosts that are missing patches. Presently, 
you can add a maximum of 2000 patches to a single job. 


Patch Management DASHBOARD PATCHES ASSETS CONFIGURATION 


=> Deployment Job, 
Uninstall Job wy 


While it is common to build a job from the JOBS section of the PM application, you can 
also create jobs within the PATCHES and ASSETS sections. 


As you will see later, you can also create from the VMDR Prioritization Report. 


<— Create: Windows Deployment Job 


Select Assets 


STEPS 2/7 
Select the assets you want this job to deploy patches on. 
Basic Information 
Include the following assets. 
Select Assets 


Selected Assets (2) 


3 Select Patches 


4 Schedule ASSET NAME Remove All 
5 Options 135355-T490 е 
6 Job Access 135355-T491 


When adding tags use this 
option to include assets with 
“Any” or “All” of the selected tags 


7 Confirmation 
Add Exclusion Assets 


Add assets directly 
to the job or use 
tags to add them 


Include hosts that have Any ғ of the tags below. Select Tags 
Any 
| Servers-HQ X | Client All x | Exchange Servers X 


You can add assets to a job by Host Name or by Asset Tag. If you include more than one 
Asset Tag, be sure to select an appropriate Boolean operator (i.e., Any or All). 


By default, the “Patch Selector” displays patches that are “Within Scope” of the hosts 
your job is targeting. 


isSuperseded: "false" = 
[ Within Scope | | 1-13 of 13 


Security Cumulative... MS20-08-W10-. KB4571694 91410 CVE-2020-1509 
Published on Aug 10, 20. 30 more. 81 more. 


Security Cumulative... MS20-08-W10-. KB4565349 91495 CVE-2020-1509 
Published on Aug 10, 20 36i more в 


MS20-08-SSU-. КВ4566424 91482 


For greater patching efficiency, consider selecting patches that have NOT been 
superseded to eliminate older, redundant patches. 


І 
Patches that display the О symbol will require a reboot. 
If you attempt to add duplicate patches, you will receive a warning message like the one 
below: 


1 or more patches listed below are already part of the selected job(s) or you might have exceeded the 
o maximum number of patches per job. Continuing will not add these repeated patches in the respective 
job(s). 


А PatchNow 1596824962760 


Duplicate patches will not be added to a job. 
You can run jobs on-demand or schedule your jobs to run at a future date and time. 


Schedule Deployment 


Schedule the deployment job to run on demand or in the future. 


| on Demand RE Schedule: Schedule the deployment job to run at a set time. 


START DATE START TIME 
08/01/2025 tig Recurring Job 


REPEATS START TIME 


Daily 12:00am 


Daily 
Timez Weekly 


Byde Monthly igent timezone. Set timezone 


Schedule jobs to run once or to recur on a daily, weekly, or monthly basis. 


You have the option to configure a "Patch Window" (i.e., "Set Duration" option) to run 
the deployment job within a specific time frame. 
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Patch Window 
You can configure a patch window to run the deployment job only within a particular time 
frame. 


None @ Set Duration ди 


Note: Setting this will restrict the agent to complete the job within the specified patch window (e.g., 


start time + 6 hrs). The job gets timed out outside this window. 


Patch Window 


6 Hours 


Select the “None” option to give a job as much time as it needs. 


The Deployment and Reboot Communication Options allow you to specify the type of 
“pop-up” messages end-users will receive before, during, and after job deployment. 


Pre-Deployment => €D 
Display message to users before patch deployment starts. 
(If no user is logged in, deployment process starts per job schedule) 


TITLE 


Pre-Deployment 


MESSAGE 


Patching is about to begin. 


DEFERMENT: NUMBER OF DEFERMENTS: 


Remind againin | 1 Hours 3 times 


The “Deferment” settings provide active end-users with the option to postpone the start 
of a job and to postpone a system reboot (if required). 


Reboot Request => €D 


Show a message to users indicating that a reboot is required. 
(If no user is logged in, the reboot will start immediately after patch deployment) 


TITLE 


Reboot Request 


MESSAGE 


Please reboot your system, to complete patch deployment. 


DEFERMENT: NUMBER OF DEFERMENTS: 


Remind againin | 1 Hours 3 times 


If no user is logged in, patching will begin as scheduled, and the host will be immediately 
following patch deployment. 


Additional Job Settings 


Enable opportunistic patch download 
The agent attempts to download patches before a scheduled job runs. 


The “Enable opportunistic patch downloads” option allows scheduled jobs to save time 
by downloading patches before execution. 


You can add assets and patches to any job that is “Disabled.” 


On Demand A | 2tw81 On-demand 15 
Install Job 13, 2020 


Scheduled - Run Опсе vew Progress Once, Nov 10 2020 12.. 7 
Install Job Edit 13, 2020 


Delete 
Recurring - Monthly Enable 2tw81 Monthly on Second T.. 5 
Install Job 13, 2020 


You can add assets and patches to a "Recurring" job, both before and after it is 
"Enabled." 


Once patch deployment is complete, another patch assessment scan will begin 


automatically, and the number of missing and installed patches will be updated for the 
affected hosts. 


Use the "Quick Actions" menu to view the progress of any job. 
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Prioritized Products 


The prioritized products report allows you to view the total number of product 
vulnerabilities (active and fixed) detected in your environment over the last two years. 


Use this report to focus on applications in your environment that are important to patch 
regularly. 


Lab 3 - https://ior.ad/7PGk 


| < Prioritized Products | 


@ This report enables you to view the total number of product vulnerabilities (active and fixed) detected in your environment over the last 2 years. 


| Nf Filters V > 


Vulnerability 
count for each 
application 


APP FAMILY NAME Applications that introduce 
most vulnerabilities in your 


environment 


VULNERABILITIES 


Windows 14939 


Chrome 13819 

Firefox 10340 | 
Edge 3833 

Java 2903 


<— Prioritized Products 


| e This report enables you to view the total number of product vulnerabilities (active and fixed) detected in your environment over the last 2 years. 


Y Filters v | ẹ 


Vulnerability Severity 


Apply tags to focus on 
vulnerabilities associated 


APP FAMILY NAME a with specific assets VULNERABILITIES 
Critical 

Windows 14939 
Important Use filters to 

narrow down to 
Chrome Moderate vulnerabilities with 13819 
] specific severities 

Low 

Firefox 10340 
None 

Edge 3833 


The "Prioritized Products" report allows you to select the required applications and 
create a deployment job. 
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< Prioritized Products 
v 


e This report enables you to view the total number of product vulnerabilities (active and fixed) detected in your environment over the last 2 years. 


г я Create а deployment job 
M | Actions v J| 0 Fiters Y || Grectiy from the "Prioritized 


Products” report 
View Related Patches VULNERABILITIES 


Create Job using Query 
14939 


The required patches are automatically identified based on your selected applications 
when you create a deployment job from the “Prioritized Products” report. This job is a 
Zero-Touch Patch Job. 


= Create: Windows Deployment Job 


STEPS 3/7 Query is populated based 


Select Patches on the applications you 

Basic Information chose 

Choose the patches you want to install for the sero» asse eate a query to automate the job. 
Select Assets 


Select Patches (D Manual Patch Selection €. Automated Patch Selection 


Select manually from the available lis Define QQL to automatically identify patches to remediate current 
Е the job runs. 


Schedule 


Options 


Patch У | XX appFamily:'Windows' or appFamily: ‘Internet Explorer’ 


Job Access 
Note: For optimum performance, only missing and non-superseded patches that match the QQL criteria will be added to the job. 


Confirmation 
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Patching from VM and VMDR 


You can create patch jobs from the VULNERABILITIES section of Qualys VM and VMDR. 


Here, patches are targeted based on the vulnerabilities they fix. 


Vulnerability v vulnerabilities.vulnerability.qualysPatchable:TRUE 


Asset Vulnerability GroupBy:.. "Y $P Filters v 
View Missing Patches {= 


372136 Mozilla Firefox Multiple Vulnerabilities (MFSA2019-31) EJEIEJETEI 
Active 


372176 Mozilla Firefox and Firefox ESR Multiple Vulnerabilities (MFSA2019-33).. EEHEHE 
Active 


372276 Mozilla Firefox and Firefox ESR Multiple Vulnerabilities (MFSA 2019-36,.. EEHEHE 
Active 


372324 Mozilla Firefox and Firefox ESR Multiple Vulnerabilities (MFSA2020-01.... вава вата] 
Active 


Not all vulnerabilities are patchable. Use this query to locate vulnerabilities that are 


patchable by Qualys’ PM module: 
vulnerabilities.vulnerability.qualysPatchable: TRUE 


After selecting one or more patchable vulnerabilities, click the “View Missing Patches” 
option to automatically begin job creation (within the Patch Management application). 
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Zero Touch Vulnerability Remediation 


Use the VMDR Prioritization report to automatically prioritize the riskiest vulnerabilities 
for your most critical assets — reducing potentially thousands of discovered 
vulnerabilities to the few that matter. 


The Prioritization Report will help you “zero in” on your highest risk vulnerabilities and 
quickly patch them by correlating vulnerability information with threat intelligence and 
asset context. 


The VMDR Prioritization report: 
e Guides you to target and quickly patch your highest risk vulnerabilities. 


e Improves your organization’s security posture by identifying and remediating the 
vulnerabilities that are most likely to get exploited. 


e Empowers security analysts to pick and choose the relevant threat indicators for 
your specific and unique organization. 


e Helps you identify the specific patch that fixes a particular vulnerability. 


e Provides an integrated workflow that reduces the time between vulnerability 
detection and patch deployment. 


Navigate to the following URL to begin the “Zero-Touch Patch Job” tutorial: 


Er? Lab 4 - https://ior.ad/7PYv 


Age (D @ (( Detection | Vuneratilty ) ^ Real-Time Threat Indicators (RTI) © е (Match Any | Match all) Attack Surface © o 


POTENTIAL IMPACT Running Kernel 


High Data Loss (319) | ( High Lateral M 


Running Service e 
(152) ) ( Privilege Escalation (194) ) ( Unauthenticated Exploitation (10) Not Mitigated by Configuration e 


Remote Code Execution (344) Remotely Discoverable Only 


ACTIVE THREATS Internet Facing Only 


Active Attacks (184) ) ( Malware (166) )( Zero Day(12) )( Public Exploit (231) 


Predicted High Risk (275) ) ( Exploit Kit (72) ) | Easy Exploit (348) 


After selecting one or more Asset tags to specify your targeted assets, prioritization 
options are provided in three categories: 


e Age: Prioritize vulnerabilities by their age. Vulnerability age is the number of 
days since the vulnerability was disclosed. Detection age is based on when the 
vulnerability was first detected (by a scanner or cloud agent). 


e Real-Time Threat Indicators (RTI): Prioritize vulnerabilities by their known and 
existing threats. Combine multiple threat indicators using the “Match Any” or 
“Match All” operators. 
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e Attack Surface: Remove vulnerabilities from the report not associated with a 


running kernel, actively running service, and other attack surface indicators. 


After selecting your prioritization options, click the “Prioritize Now” button. 


< УМОК Prioritization 


( Export to Dashboard ) ( Save & Download )} 


Prioritized Assets © Prioritized Vulnerabilities © 


Available Patches © Details 
@ 100% © Instances 47.08% © Unique o 
ne ок 
of 1 


of 325 
Create a Zero-Touch Patch Job 


for the prioritized vulnerabilities 


e Zero-Touch Patch Job © 
Vulnerabilities | Patches | Assets and available patches 
Windows Patches 74 
View Missing Windows Patches 
Patch “а H @ 
Deploy individual patches 
Group By:.. wv 1-50 of 74 D co 
PATCH TITLE 


ARCHIT BULLETIN/KB OR TYPE 00 VENDOR SEVER MISSING 

ADVISORY ID 

MS21-04-SSU-5001... 
KB5001403: Servicing stack update for Windows 8.1, Windows RT 8.1, and Wi... x64 Шосе 05 91653 1 “( Patch now м ) 
Security and Quality Rollup for .NET Fi rk 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7... X64 ND MRNETAS-. og 21437 1 ( расһмом v) 
ecurity and Quality Rollup for . ramework 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7... prc) пре : 


The displayed assets, vulnerabilities, and patches will reflect the prioritization options 
you specified. 
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Uninstall Job 


You can create an “Uninstall Job” for agent hosts that already have patches installed. 
However, not all patches are candidates for an uninstall or “rollback” operation. 


| Patch Management v | New Updates DASHBOARD PATCHES ASSETS JOBS CONFIGURATION | 


Windows 


Create a patch 
uninstall job 


Total Job 


STATUS ee OWNER | SCHEDULE 
Uninstall Job | 
Completed rs quays2nd84 Once, Jul 10, 2021 03:55 pm 
STATUS Install Job Jul 09, 2021 
Completed 1 


Navigate to the following URL to view the “PM Uninstall Job” tutorial: 


Lab 5 - https://ior.ad/7PHG 


Only “Rollback” patches in the catalog are candidates for an Uninstall Job. 


Path v [X isRollback: true «Дежа 
н Re 1-Soot 85 


View Details 


Add to Existing Job 
BULLETIN / KB 
Add to New Job 


Remove Patch <= MS20-08-IE-4571687 91332 
72020 KB4571687 88 more 
August 11, 2020-KB45.. MS20-08-S081-457... 373321 
Published on Aug 10, 2020 KB4571723 1 more. 


Security Monthly Rollu... MS20-08-MR81-457... 91413 
Published on Aug 10, 2020 FEAR До more 


When displaying a list of patches, this query will list the uninstallable or “rollback” 
patches -isRollback: true 
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List: Uninstallable Patches 


Q Search for patch... 


120 в =) e vo 1-5001 120 cn 
Total Patches 


PATCH TITLE ARCHIT BULLETIN KB TYPE 00 


A Security Monthly Ro.. © X64  MS20-04-MRB. KB4550961 os 91413 CVE-2020-0938 
SUPERSEDED Published on Apr 13, 20... 197 mare: пол. 
false 108 E Servicing stack upd.. (© x64  MS20-03-SSU-.. КВ4540725 os - - 
true 12 Published on Mar 09, 20. 
i j = X64  MSNS20-01-44. KB4486105 os - None - 
APP FAMILY Microsoft .NET Fra o 


Published on Jan 13, 20... 
Windows 115 


Internet Explorer. 5 


Security and Quality.. © X64 MS20-01-MRN.. КВ4532940 
lished qq. Jap 13, 20... 


СУЕ-2020-0605 


By default (when going through the steps to build an Uninstall Job), the list of 
“uninstallable” patches displayed is “Within Scope” of your targeted hosts. 
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PM Patches 


The Patch Catalog contains tens of thousands of OS and application patches. Presently 
you can add up to 2000 patches to a single job. 


Navigate to the following URL to view the “PM Patches” tutorial: 


PLAY 4 Lab 6 - https://ior.ad/7Ple 


By default, only the latest (non-superseded) and missing patches are displayed. This is 
done to help you focus on the essential patches required by your hosts. 


| Patch Status: Missing Only Latest Patches (Non-superseded) 


Yes 


À Filters v <= 


Patch Status 


v| Missing 


Installed 


Firefox 79 ЕЕ 
Published o Only Latest Patches (Non-superseded) OF 

[7] Yes 
$ Java 8 Ир JA 
Published on Jul 13, 2020 QJ 


To view all patches in the catalog, remove (uncheck) the “Missing” and “Non- 
superseded” filter options and then click somewhere outside of the “Filters” drop-down 


menu (to refresh the displayed patches). 


Any query entered in the “Search” field will be affected by these filter options. 


Patch M downloadMethod:AcquireFromVendor 
Y Filters v 
Microsoft Power BI De.. 0 X64X.. РВІР-200728 
Published оп Jul 27, 2020 QBI2835894881 
Microsoft Power BI De... ®© x64 PBID-200728 
Published on Jul 27, 2020 QBI2835894881 


Qualys Cloud Agent cannot download patches identified with the “key-shaped” icon. 
Use this query to identify such patches - down loadMethod: AcquireFromVendor 
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Patch M 


isRollback:true <= 


View Details 


Add to Existing Job 
Add to New Job 


M Remove Patch = [9] 
Dx 72020 
August 11, 2020-КВ45.. [9] 
Published on Aug 10, 2020 
Security Monthly Rollu... [9] 


Published оп Aug 10, 2020 


1-50 of 85 


MS20-08-IE-4571687 OS 


или 1 oO 


KB4571687 more 

X64 М520-08-5081-457.. OS 373321 1 0 
KB4571723 imos 

X64 М520-08-МА81-457.. OS 1 0 


7) 


isRollback:true 


The "Rollback" patches in the catalog are candidates for an Uninstall Job. Not all 


patches can be uninstalled. 


Patch jobs can also be created and updated from within the PATCHES section of the 
Patch Management application. 


On Demand 
Install Job 


Scheduled - Run Once 
Install Job 


Enabled | 


Recurring - Monthly 
Install Job 


trann2tw81 On-demand 15 0 3 | PM Lab 
Aug 13, 2020 

trann2tw81 Once, Nov 10202012. 7 1 0 

Aug 13,2020 

trann2tw81 Monthly on Second T... 5 3 0 

Aug 13, 2020 


Additional patches can be added to any existing job that is disabled. Additional patches 
can be added to a recurring job, both before and after it is enabled. 
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РМ Assets 


The ASSETS section of the Patch Management application displays agent hosts that have 
the Patch Management module activated. 


Navigate to the following URL to view the “PM Assets” tutorial: 


Lab 7 - https://ior.ad/7PHR 


Scanned ee Microsoft Windows S... 
Scanned on Aug 05, Quick Actions 


Scanned = View Details Microsoft Windows S.. .\Administrat... 


Scanned on Aug 05,... 
Add to Existing Job 


Scanned v Microsoft Windows S.. .\Administrat... 
Scanned on Aug 05, Add to New Job 


Scanned WIN10DFW239 Microsoft Windows 1.. .\qscan 
Scanned on Aug 05,.. 


Only assets that have been successfully scanned will display their number of MISSING 
and INSTALLED patches. 


< Asset Details: EC2AMAZ-EJUF25M 


v. INVENTORY 
Asset Summary 


Asset Summary 


System Information 


EC2AMAZ-EJUF25M 
Network Information 
Microsoft Windows Server 2019 Datacenter (1809 64-Bit) 


Open Ports Amazon Web Services 


Installed Software 


EC2 Information Identification Last Location 
DNS Hostname ec2amaz-ejuf25m 
v SECURITY 
FQDN EC2AMAZ-EJUF25M. WORKGROUP 
Vulnerabilities 
Threat Protection Бари Eerie ЗМ 9 
Patch Management <= IPv4 Addresses : 172.31.26.105, 3.129.128.195 | Columbus, Ohio United States 
ae z | 2 : 
Indication of Compromise IPv6 Addresses:  fe80:0:0:0:6d1 5:f2ac:fa5c:9720 ease o U 
| от: 3.1 
Certificates ; 
Asset ID: 75439775 
v COMPLIANCE Host ID: 102475952 
File Integrity Monitoring 
Agent Activity 5. Tags AddTags 
v SENSORS Last User Login Е | Cloud Agent £ | PMLab £ 
Agent Summary Last System Boot 6 days ago 01:08 pm 


The asset details include system information, network information, installed software, 
findings provided by other Qualys modules and applications, assigned Asset Tags, and 
more. 
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MISSING PATCHES 


TOP 5 RECENT MISSING PATCHES 


July 21, 2020-KB4567... 


Cumulative Update for ... 


„МЕТ Fi 


Patch Management 


MSNS20-07-MR.. 


MSNS20-07-W1... 


3 view 


@ Critical 


В Important 0 
80 Moderate 0 
|| 


Low 


None 


none 


none 


none 


Open in Patch 
Management EJ 
View All (22) 
INSTALLED PATCHES 
1 9 view 


+ 


В Critical 16 


В пропам 1 
B Low 0 
Мопе 2 


ТОР 5 DEPLOYED PATCHES 


Microsoft Edge 84.0.5.. MEDGE-200803 3 days ago 


July 14, 2020-KB4566... MS20-07-MRNE...  Jul13,2020 


я S20:07-S: 113,202 


The graphics and illustrations displayed are interactive, giving you the ability to “click” 
and focus on different host findings and attributes. 


Both Deployment and Uninstall Jobs can be created from within the ASSETS section. 


On Demand 
Install Job 


Scheduled - Run Once 
Install Job 


Recurring - Monthly 
Install Job 


trann2tw81 
Aug 13, 2020 


trann2tw81 
Aug 13, 2020 


trann2tw81 
Aug 13, 2020 


1EDL ATCHI ASSETS 


On-demand 15 0 3 | PM Lab 
Once, Nov 10 2020 12.. 7 1 0 
Monthly оп Second T.. 5 3 0 


Additional assets can be added to any existing job that is disabled. Additional assets can 
be added to a recurring job, both before and after it is enabled. 
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Qualys Patch Management Certification 
Exam 


Participants in the Qualys Patch Management training course have the option to take the 
associated certification exam. This exam is provided through our Learning Management System 
(LMS) at qualys.com/learning — candidates will need an account on this system to take the 
exam. 


Qualys. Training & Certification 


Please log in to the Qualys training site. First time users 
need to create an account. 


*Required Field 


* Username: 


* Password: 


Forgot your password? Request a new account. 4——— 


If you would like to take the exam, but do not already have a "learner" account, click the 


“Request a new account” link, from the LMS at http://qualys.com/learning. 


Once you have created a "learner" account (and for those who already have an account), click 
the following link to access the "Patch Management - QSC 2021" course page: 
https://gm1.geolearning.com/geonext/qualys/scheduledclassdetails4enroll.geo? &id=225 11237815 
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Course Catalog: Class Details 
Course: Patch Management - QSC 2021 


To see how a class below fits into your schedule, click View My Class Schedule. 


CLASS DETAILS: PATCH MANAGEMENT - QSC 2021 
Course Name: Patch Management - QSC 2021 
Class Name: Patch Management - QSC 2021 
Class Code: 2250729076520210917124317 
Contact Name: Shyam Raj 
Private Class: Yes 
Maximum Class Capacity: 5000 
Class Cost: $0.00 


Click here 
to enroll 


Session Location Classroom Address Address City State Postal Times Instructor(s) 
Name 4 1 2 Code 
Session 1 N/A N/A N/A N/A N/A N/A N/A Monday, November 15, 2021 9:00 AM to 1:00 PM 'am Raj 


(America/Los Angeles) (UTC -07:00) 


View My Class Schedule 


From the “Patch Management - QSC 2021" course page, click the “Enroll” button (lower-right 
corner). 


After successfully completing the course enrollment, click the "Launch" button, for the Qualys 
Patch Management Exam. 


Patch Management - QSC 2021 


Progress: Not Attempted Status: Enrolled Required: No Duration: 4 hours 


| Drop Class | Drop Course 


= Activities 


Class Sessions 


Class Name Date Location Classroom Instructor(s) 
Patch Management - QSC 2021 Monday, November 15, 2021 9:00 AM to 1:00 PM (America/Los_Angeles) (UTC -07:00) N/A N/A Shyam Raj 


To access a learning activity, select the activity name and click Launch or Open. 


Click here to launch 
the exam 


Activity Name 4 Type Progress Last Accessed Time Taken Attempts Action 


Qualys Patch Management (PM) Exam Actual Test Not Attempted N/A N/A N/A 


Each candidate is provided five attempts to pass the exam. 
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Progress: Completed Status: Enrolled Required: No Duration: 4 hours 


Patch Management - QSC 2021 


Click here to print 
your certificate Print Certificate 


— Activities 


Class Sessions 


Class Name Date Location Classroom Instructor(s) 
Patch Management - QSC 2021 Monday, November 15, 2021 9:00 AM to 1:00 PM (America/Los_Angeles) (UTC -07:00) N/A N/A Shyam Raj 


To access a learning activity, select the activity name and click Launch or Open. 


Activity Name a Type Progress Last Accessed Time Taken Attempts Action 


Qualys Patch Management (PM) Exam Actual Test Passed 10/13/2021 9:02:25 AM Oh 6m 1 


With a passing score of 7596 (or greater), click the "Print Certificate" button to download and 
print your course exam certificate. 


Training Survey 


Please take a moment to take the survey about today's training - 
https://forms.office.com/r/rsyOAja6Xz 
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